- Securonix uncovers SMOKE#SCREEN, a campaign tricking users into installing weaponized ScreenConnect via fake Zoom/Adobe updates and business docs
- Attackers gain persistent remote access, evolving tactics to disable protections and abuse trusted services like Dropbox/Cloudflare for delivery
- Victims observed on Windows and macOS; businesses urged to verify updates via official sites and train staff against unexpected installs
Security experts Securonix Threat Research have uncovered a new malicious campaign that tricks users into installing legitimate remote monitoring and management (RMM) software.
Dubbed SMOKE#SCREEN, the campaign uses fake Zoom and Adobe update messages, as well as a whole swathe of fraudulent business-related documents (document review requests, system maintenance tools, invoices, and similar), to convince the victims to run malicious files.
Victims who don’t see through the ruse and run the files end up installing ConnectWise ScreenConnect, a legitimate RMM tool that many IT teams use to provide technical support to their coworkers and clients. However, it is also one of the more abused solutions in the criminal cyber-underworld, since it can often fly under the radar of security products.
Dangerous evolution
After installation, attackers can remotely access compromised devices, potentially allowing them to steal data, install additional threats, or move deeper into an organization’s network.
At first glance, SMOKE#SCREEN looks like a fairly standard “phishing – install legitimate RMM – remote access” campaign. However, what makes it unique is how it evolved over time, Securonix explained. Earlier versions focused on hiding the malicious activity, while newer versions attempted to disable security protections and avoid detection by security software. The attackers also used trusted services such as Dropbox and Cloudflare to deliver their files, making the activity harder to block.
Victims were observed on both Windows and macOS ecosystems, it was added.
“The SMOKE#SCREEN campaign demonstrates a capable, actively maintained, and rapidly adapting threat actor who has built a diversified toolkit around a single objective: gaining persistent, legitimate-looking remote access to victim systems through weaponized ScreenConnect deployments,” the researchers explained.
“The use of multiple social engineering themes, rotating payload hashes, cross-platform coverage, and a live staging server that doubles as a ScreenConnect relay indicates a well-resourced actor with deliberate operational security practices.”
To minimize the risk of compromise, businesses should disable receiving software updates delivered through emails, verify update requests through official websites, and instruct their employees to be cautious when opening attachments or installing tools they were not expecting.
Via The Hacker News
